CVE-2026-60990: Critical severity Oracle Oracle Fusion Middleware - Oracle Identity Manager Connector (Core) vulnerability
Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TLS to compromise Oracle Identity Manager Connector. While the vulnerability is in Oracle Identity Manager Connector, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Identity Manager Connector. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Identity Manager Connector (Core)to a version that resolves this vulnerability.Fixed in 12.2.1.4.0 - Upgrade
Upgrade
Oracle Fusion Middleware - Oracle Identity Manager Connector (Core)to a version that resolves this vulnerability.Fixed in 14.1.2.1.0
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker needs network access to the affected Oracle Identity Manager Connector service over TLS and must already have low-privileged access. No user interaction is required.
Which deployments are known to be affected?
Affected supported versions are 12.2.1.4.0 and 14.1.2.1.0 of the Oracle Identity Manager Connector Core component in Oracle Fusion Middleware.
What is the potential impact of successful exploitation?
Successful exploitation can allow takeover of Oracle Identity Manager Connector with high impact to confidentiality, integrity, and availability. Because the vulnerability has scope change, attacks may also significantly affect additional products.